Try it free

Manage security integrations with Security Operations

  • Latest Dynatrace
  • How-to guide

Centrally manage all security ingest connections from a single app.

Overview

Security Operations Security Operations provides a unified interface to create, configure, and manage connections to third-party security products. Each connection establishes a dedicated ingest pipeline that routes security findings into the Dynatrace security.events Grail bucket via OpenPipeline.

It provides a single interface to:

  • Create connections for supported security products and cloud services
  • Follow guided onboarding instructions for each integration
  • Validate ingest using sample events and a DQL-based verification query
  • Monitor the health and data flow of all integrations from a central view
  • Manage connection access, sharing, and lifecycle
  • Install pre-built dashboards and workflows that provide immediate operational value

Supported integrations

IntegrationCategory

Amazon GuardDuty

Alerts & detections

Amazon ECR

Code & build artifact scanners

AWS Security Hub

Security posture

Google Artifact Registry

Code & build artifact scanners

Microsoft Defender for Cloud

Security posture

Microsoft Sentinel

Alerts & detections

OCSF generic ingest

Generic

Deprecation of legacy push-based integrations

Security Operations Security Operations replaces the following standalone, push-based app integrations that are now deprecated:

  • Amazon GuardDuty (standalone app)
  • Amazon ECR (standalone app)
  • AWS Security Hub (standalone app)
  • Microsoft Defender for Cloud (standalone app)
  • Microsoft Sentinel (standalone app)
  • OCSF (standalone app)

If you have existing connections configured in any of these legacy apps, migrate them to Security Operations Security Operations and uninstall the legacy apps. See Migrate from legacy integrations.

Use cases

With security findings ingested through Security Operations Security Operations, you can accomplish the following use cases.

  • Automate and orchestrate security findings
  • Visualize and analyze security findings
  • Discover coverage gaps in security findings
  • Monitor suspicious sign-in activity with Dynatrace
  • Runtime contextualization of container findings

Get started

Requirements

To use Security Operations Security Operations, you need the following Dynatrace platform permissions.

ActionRequired permission

View connections

app-settings:objects:read

Create or modify connections

app-settings:objects:write

Delete connections or manage sharing

app-settings:objects:admin

Query ingested data

storage:security.events:read

Create a connection

  1. In Dynatrace, open Hub.
  2. Search for the integration you want to set up (for example, Amazon GuardDuty) and select Install.
  3. Select Set up, then select Configure new connection.
  4. Enter a Name for the connection and follow the on-screen onboarding instructions for the selected integration.
  5. Select Create to save the connection and generate a scoped ingest token.

After creating the connection, the onboarding instructions guide you through the provider-side setup—for example, deploying a CloudFormation stack for AWS integrations or a Bicep template for Azure integrations.

You can also access Security Operations Security Operations directly via Settings > Collect and capture > Security data.

Validate ingest

After completing provider-side setup, verify that data is flowing:

  1. In Security Operations Security Operations, select the connection you want to verify.
  2. Select Send sample event. The app sends a pre-defined sample event through the ingest endpoint.
  3. A DQL-based validation query runs automatically. A successful result confirms the sample event reached Grail and was processed correctly.

Monitor integration health

Security Operations Security Operations provides a central view of all your security integrations in one place, so you can assess the health and data flow of every connection without switching between individual integration screens.

From the main view, you can see:

  • An aggregated ingest chart showing event volume across all connections over time—a flat line or sudden drop signals that an integration has stopped sending data
  • A connections table listing every configured connection, its integration category, and the last time data was received
  • Per-connection detail with an individual ingest chart, connection configuration, and the validation status from the last sample event test

Use this view to detect stalled or misconfigured integrations early and to confirm that provider-side changes (such as a rotated API key or a redeployed CloudFormation stack) have taken effect.

Edit a connection

  1. In Security Operations Security Operations, select the connection you want to edit.
  2. Select Edit.
  3. Modify the connection settings and select Save.

Delete a connection

Deleting a connection removes the ingest pipeline and revokes the associated ingest token. Existing data in Grail is not affected.

  1. In Security Operations Security Operations, select the connection you want to delete.
  2. Select Delete and confirm.

Share a connection

Sharing controls who can view, use, or modify a connection. By default, only the connection owner has access.

To share a connection:

  1. In Security Operations Security Operations, select the connection.
  2. Select Share.
  3. Add users or groups and assign an access level:
    • Viewer — can view the connection and its configuration
    • Editor — can edit the connection settings
    • Admin — can edit, delete, and manage sharing

Ready-made dashboards and workflows

Dashboards are available for discovery immediately after you create a connection. Deploy workflows before they run—no DQL knowledge or manual configuration is required.

Dashboards

Dashboards are automatically available as ready-made dashboards once a connection exists. Open Dashboards Dashboards and browse Ready-made dashboards, or access them directly from the connection detail view in Security Operations Security Operations.

DashboardDescription

Audit logs

Audit log activity ingested from third-party platforms

Container image alert reduction

Runtime contextualization of container findings for alert reduction

Container scan events coverage

Coverage report for container image scan events

Container vulnerability findings

Vulnerability findings in container image artifact registries

Emerging threat intelligence reports

Newly reported threat intelligence, grouped by source and severity

Host vulnerability findings reduction

Runtime contextualization of host findings for alert reduction

Security findings

Overview of security findings reported across all connected products

Security product coverage

Overview of security coverage across entities and environments

Sign-in activity monitoring

Sign-in attempts, failures, and anomalies from ingested identity logs

SonarQube posture overview

Code quality and security posture reported by SonarQube

Threat exposure analysis

Correlates threat intelligence with observed logs and traces to gauge exposure

Track remediation with vulnerability scans

Remediation progress measured across successive vulnerability scans

Vulnerability findings

Overview of vulnerability findings reported across connected products

Web network activity

Web and network request activity from ingested logs and traces

Workflows

Workflows automate the handling of incoming security findings. Unlike dashboards, workflows must be explicitly deployed before they run.

WorkflowDescription

Email on new critical security findings

Sends an automated email notification whenever new critical-severity findings are ingested

Jira ticket for critical container vulnerabilities

Files one Jira ticket per run for new critical container vulnerability findings

Jira ticket for critical vulnerabilities

Files one Jira ticket per run for new critical vulnerability findings

Slack notification for critical container vulnerabilities

Sends one grouped Slack digest for new critical container vulnerability findings

Slack notification for critical vulnerabilities

Sends one grouped Slack digest for new critical vulnerability findings

Not all templates are available for every integration. The templates shown in Security Operations Security Operations and in each app reflect only those that apply to your configured connections.

Deploy a workflow

To deploy a Security Operations workflow template:

  1. In Workflows Workflows, select +Workflow.
  2. Under Security Operations, select the workflow template you want to deploy.
  3. Review the configuration and select Save.

Alternatively, you can start deployment from the connection detail view in Security Operations Security Operations.

Migrate from legacy integrations

If you have connections configured in a legacy standalone app, migrate them to Security Operations Security Operations to benefit from centralized management, improved sharing controls, and future updates.

Security Operations Security Operations includes step-by-step migration instructions for each legacy integration directly in the app.

To migrate:

  1. In Dynatrace, open Security Operations Security Operations.
  2. Select Migrate connections. The app lists all legacy connections it can detect and walks you through re-creating them as managed connections.
  3. After verifying that the new connections are ingesting data correctly, follow the in-app instructions to uninstall the legacy app.

Related topics

  • OpenPipeline
  • Dynatrace Query Language
  • Security events
Related tags
Threat Observability